Re: [Pdns-users] pdns error sendto

2011-02-28 Thread Nick Milas
In CentOS 5, I directly edit iptables file. I'm using the following DNS rules for iptables (as suggested by RH/CentOS), and I have no problems with DNS servers: -A RH-Firewall-1-INPUT -m state --state NEW -p udp --dport 53 -j ACCEPT -A RH-Firewall-1-INPUT -m state --state NEW -p tcp --dport 53

Re: [Pdns-users] pdns error sendto

2011-02-28 Thread Bart Smit
Liong Kok Foo wrote: > What other iptables firewall you guys > are using for CentOS? I used APF because it is something easy to > configure and it was working fine years ago when I started using it. Personally I wouldn't put a DNS server behind any stateful firewall at all. Validating DNS reply p

Re: [Pdns-users] stuck tcp sessions on recursor

2011-02-28 Thread Charles Sprickman
On Thu, 24 Feb 2011, bert hubert wrote: On Thu, Feb 24, 2011 at 03:06:12PM -0500, Charles Sprickman wrote: this definitely sounds like 3.3 material! So far so good, nearly 500,000 tcp queries without any lingering sockets. Good! Totally unrelated, but I see a stat that's not mentioned in